MiNiFi CPP arbitrary script execution is possible on the agent's host machine through the c2 protocol
Vulnerability Description
From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. This "patching" command defaults to calling a trusted binary, but might be modified to an arbitrary value through a "c2-update" command. Said command is then executed using the same privileges as the application binary. This was addressed in version 0.10.0
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-33191
Credits & Attribution
No credits recorded in the NVD database.
References
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →